I'm planning on getting two new Palo Alto firewalls for setting up IPSec tunnels. I think the first tunnel will be a primary tunnel and the second tunnel will be back up. I'm tempted to set up my new firewalls as active/passive HA, to make life easy. But to be sure, please could someone suggest what are the advantages of using active/passive compared to active/active for dual IPSec tunnels?
I'm going to be using BGP over the IPSec tunnels and BGP to the LAN, so if I go for the active/passive option, it just means i dont have to double up my BGP peers...
Any links to the best practices for BGP and IPSec HA would be appreciated... thanks
Agreed with @OtakarKlier; in your situation it doesn't matter if you deploy A/P or A/A as far as the VPN tunnels go, makes no change to how you are going to do things really. There aren't a lot of use cases where I would really recommend an Active/Active Palo Alto deployment to be honest, there are far too many issues that are present in A/A deployments.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!